Real-world descriptions of how a group, tool or campaign used a technique.
63 examples
| Technique | Used by | Procedure example |
|---|---|---|
| T1036.005 Match Legitimate Resource Name or Location |
GroupINC Ransom | INC Ransom has named a PsExec executable winupd to mimic a legitimate Windows update file. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupEarth Lusca | Earth Lusca used the command `move [file path] c:\windows\system32\spool\prtprocs\x64\spool.dll` to move and register a malicious DLL name as a Windows print processor, which eventually was loaded by the Print Spooler service. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSilence | Silence has named its backdoor "WINWORD.exe". |
| T1036.005 Match Legitimate Resource Name or Location |
GroupSowbug | Sowbug named its tools to masquerade as Windows or Adobe Reader software, such as by using the file name adobecms.exe and the directory |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVelvet Ant | Velvet Ant used a malicious DLL, `iviewers.dll`, that mimics the legitimate "OLE/COM Object Viewer" within Windows. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTransparent Tribe | Transparent Tribe can mimic legitimate Windows directories by using the same icons and names. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupVOID MANTICORE | VOID MANTICORE has masqueraded malicious payloads to resemble legitimate applications. VOID MANTICORE has leveraged malicious payloads that use nomenclature associated with common applications that include Pictory, KeePass, WhatsApp, and Telegram. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupPROMETHIUM | PROMETHIUM has disguised malicious installer files by bundling them with legitimate software installers. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupWIRTE | WIRTE has used security service provider naming conventions such as ESET and Kasperky ("Kaspersky Update Agent") in order to appear legitimate. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupMagic Hound | Magic Hound has used `dllhost.exe` to mask Fast Reverse Proxy (FRP) and `MicrosoftOutLookUpdater.exe` for Plink. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupFIN13 | FIN13 has masqueraded WAR files to look like legitimate packages such as, wsexample.war, wsexamples.com, examples.war, and exampl3s.war. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupTeamPCP | TeamPCP has cloned GitHub commit metadata including the author name, email, committer, and timestamps to use for impostor commits. TeamPCP has also used legitimate file names such as msbuild.exe and ringtone.wav to mask malicious payloads. |
| T1036.005 Match Legitimate Resource Name or Location |
GroupShinyHunters | ShinyHunters has disguised MeshCentral agent binaries as Microsoft Azure services, e.g. meshagent32-azure-ops.exe, meshagent64-azure-ops.exe, and meshagent64-v2.exe. |
Data from MITRE ATT&CK® (Enterprise). ATT&CK® is a registered trademark of The MITRE Corporation.